Checked on September 27, 2026
NIS2 in Denmark
How Denmark applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.
- Transposition status
- In force
- National law
- Act on measures to ensure a high level of cybersecurity (NIS 2 Act) · Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau (NIS 2-loven), lov nr. 434 af 2025 · from July 1, 2025
- Competent authority
- Danish Agency for Societal Security (SAMSIK), with sector-responsible authorities (Styrelsen for Samfundssikkerhed)
- National CSIRT
- National CSIRT at the Danish Defence Intelligence Service (Forsvarets Efterretningstjeneste)
- Registration
- Required · Portal · deadline October 1, 2025
Registration via virk.dk with MitID Erhverv; opened 2025-07-01.
- Incident reporting
- Via virk.dk, forwarded automatically to the sector authority and the national CSIRT (FE): early warning 24h, update 72h, final report within 1 month.
- National specifics
- Adopted by the Folketing on 2025-04-29 (bill L 141).
- Supervision is sector-based: sector-responsible authorities oversee entities in their sectors.
Where does your company stand?
The free assessment applies these national rules to your answers and scores every area of the law.
Sources
National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.